Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Security Event 4656: SAM Registry Hive Key Handle Requested
Flags Windows handle requests to registry keys ending with \SAM using Security EventID 4656.
sigmaWindowshigh2019-08-12Cisco AAA local account and remote authentication changes
Flags Cisco AAA log events showing local username/account changes and remote authentication configuration updates.
sigmaNetworkhigh2019-08-12Cisco IOS AAA Crypto PKI Export/Import Commands
Alerts on Cisco IOS AAA logs showing crypto PKI export of private keys or PKI import of certificates/trustpoints.
sigmaNetworkhigh2019-08-12Cisco Network OS Log and Archive Clearing via “clear logging” Commands
Flags Cisco network OS attempts to clear logs or archives via AAA command text.
sigmaNetworkhigh2019-08-12Cisco IOS AAA Logging Disabled via 'no logging' and 'no aaa new-model' commands
Flags Cisco AAA command text that includes 'no logging' and/or 'no aaa new-model' to indicate logging being turned off.
sigmaNetworkhigh2019-08-11Windows Remote PowerShell Session via PS Module ContextInfo and wsmprovhost.exe
Flags Windows PowerShell remote session module context involving wsmprovhost.exe while filtering out archive module references.
sigmaWindowshigh2019-08-10Windows Security: Network Access to protected_storage (IPC)
Flags Windows network share access to protected_storage through IPC from Security event 5145.
sigmaWindowshigh2019-08-10Windows: MMC spawning command-line executables
Flags cases where mmc.exe starts command-line tools like cmd, PowerShell, script hosts, or BITSADMIN.
sigmaWindowshigh2019-08-05Windows CMSTP UAC Bypass Attempt via Autoelevate COM Object DllHost Execution
Detects DllHost.exe spawning CMSTP-related autoelevate COM objects by matching known Processid values and high/system integrity.
sigmaWindowshigh2019-07-31Windows Process Creation: Executable Extension Masquerading with .exe After Decoy Extension
Alerts on Windows processes whose paths/command lines use misleading double extensions ending in .exe to cloak executable execution.
sigmaWindowshigh2019-06-26Windows Security Event 4662 Detects DPAPI Domain Backup Key Extraction from Domain Controllers
Detects read access to LSA secret DPAPI domain backup key objects in Windows Event ID 4662.
sigmaWindowshigh2019-06-20Windows Process Creation: Flag Renamed Execution of Common LOLBins Based on OriginalFileName
Alerts when a renamed process executes and Sysmon OriginalFileName matches common Windows LOLBins, suggesting defense-evasion rename behavior.
sigmaWindowshigh2019-06-15Windows Process Creation: Renamed jusched.exe Execution via Java Scheduler Names
Alerts when Java Update Scheduler descriptions are used to execute a process ending with \jusched.exe on Windows.
sigmaWindowshigh2019-06-04Windows Security 4625 Logon Failures to TargetUserName AAAAAAA Indicative of RDP Scan PoC
Alerts on Windows failed logon (4625) events matching a BlueKeep scanner PoC TargetUserName value.
sigmahigh2019-06-02Windows Terminal Service Parent Process Spawn (svchost.exe termsvcs)
Alerts when a new process is spawned under a Terminal Services (termsvcs) host context in Windows.
sigmaWindowshigh2019-05-22Potential BearLPE Exploitation via Windows Task Scheduler schtasks.exe DACL Change
Flags schtasks.exe executions with /change, /TN, /RU, and /RP, consistent with task modification tied to BearLPE attempts.
sigmahigh2019-05-22WinRM Remote Access to LSASS via wsmprovhost.exe (Windows Process Access)
Flags remote WinRM (wsmprovhost.exe) process-access to lsass.exe, a high-risk credential-access behavior.
sigmaWindowshigh2019-05-20Windows PowerShell Script Block Logging: Nishang Commandlet Names and Arguments
High-severity alert on PowerShell script blocks that reference known Nishang commandlets and exfil/execution helper names.
sigmaWindowshigh2019-05-16Windows: Outbound RDP (3389) Connections Initiated by Non-Standard Processes
Alerts on outbound port 3389 connections on Windows when initiated by an unapproved process, suggesting non-standard RDP tooling.
sigmaWindowshigh2019-05-15Windows PowerShell Process Creation With Empire-Style EncodedCommand Launch Parameters
Flags PowerShell command lines containing hidden/stealth and encoded Empire-style launch parameters on Windows.
sigmaWindowshigh2019-04-20